> Why would you have to reconfigure your firewall rules when you're getting a new IPv6 prefix?
Because the IP address of the target changes when you get a new prefix.
There's some discussion in this[1] old pfSense ticket.
With IPv4 you typically do address translation (NAT) and so the internal target address is not tied to the global address.